Privacy Policy for the Members of the Board of Directors of Yandex N. V.

This is an old version of the document, which expired on August 23, 2022. The current version is available at: https://yandex.com/legal/privacy_policy_board_members_yandex_n_v.

 

Last updated: April 12, 2021

This Privacy Policy for the Members of the Board of Directors of Yandex N. V. (the “Privacy Policy”) is designed to provide data subjects (individuals) with information on the processing of their personal data (any information relating to them) when they interact with Yandex N. V. (Schiphol Boulevard 165, 1118 BG Schiphol, Netherlands) (“Yandex”) in the context of their membership in the Board of Directors of Yandex.

This Privacy Policy refers to the provisions of the General Data Protection Regulation (GDPR) as in force on the date of the last update of this Privacy Policy.

1. Controller

Yandex is a controller of personal data processed under this Privacy Policy. It means that Yandex determines the purposes and means of the processing of these personal data.

The members of the Board of Directors of Yandex can contact Yandex on any questions relating to the processing of their personal data by either of the following methods:

Email: gdpr@yandex-team.com

Postal address: Schiphol Boulevard 165, 1118 BG Schiphol, Netherlands

Phone number: +31 0 20 206 6970

2. Purposes and legal bases for the processing

Yandex processes personal data to comply with applicable corporate and other laws and to enter into and perform the relationships with the members of its Board of Directors. When doing so, Yandex relies on the necessity of the processing of personal data to comply with its legal obligations and the necessity of the processing of personal data for the purposes of the legitimate interests pursued by Yandex. In some cases, Yandex may ask for consent of a data subject to use his or her personal data.

The legitimate interests of Yandex consist of compliance with applicable corporate and other laws and regulations (other than European Union law or European Union member state law), and of usage of resources of Yandex affiliates for assisting it in the achieving of legal purposes of the processing. Data subjects can get more information on the legitimate interests pursued by Yandex and relevant balancing tests by sending a request with the use of contact details specified in section 1 of this Privacy Policy.

3. Categories of personal data concerned which are not obtained from data subjects

Yandex uses its affiliates to collect and otherwise process personal data of the members of its Board of Directors. These affiliates are independent controllers of the relevant personal data. Yandex gets from them the following categories of personal data of the members of its Board of Directors:

1) name and surname;

2) date of birth, age;

3) nationality;

4) home address;

5) phone number;

6) BSN number, identification tax number;

7) email address;

8) identification card number/passport number, date of issuance, the authority that issued the passport, other passport details;

9) information about positions in other companies and prior places of work for five years prior to the appointment;

10) information on any claim, investigation or proceeding initiated, conducted or being conducted by any Russian, Dutch or U.S. federal or state regulatory, civil or criminal agency, or any other regulatory, civil or criminal authority;

11) information about commercial relationships which can cause a conflict of interest;

12) information about sanctions or other restrictions/prohibitions/bans that may affect the data subject’s work on the Board of Directors of Yandex;

13) information about the data subject’s compensation package in Yandex;

14) information about the data subject’s shareholding in Yandex, including transactions with the Company’s securities;

15) information about shareholding interest in 10% or more of the voting power;

16) board membership or membership in other governing bodies in other companies;

17) information on spouses, children, and other close relatives including their names, their commercial relationships with audit companies retained by Yandex, and their compensations received from Yandex.

4. Recipients of personal data

Yandex discloses certain personal data of the members of the Board of Directors of Yandex to the following recipients to the extent required or permitted by applicable law and/or based on their legitimate and reasonable requests:

1) U.S. Securities and Exchange Commission;

2) Dutch Central Bank (De Nederlandsche Bank);

3) Central Bank of Russia;

4) Federal Antimonopoly Service of the Russian Federation;

5) Moscow Exchange;

6) Nasdaq Stock Market;

7) U.S. FINRA (Financial Industry Regulatory Authority);

8) Yandex LLC registered at Leo Tolstoy street, Moscow, Russia, 119021;

9) members of the public (via website);

10) duly appointed independent auditors of Yandex and (or) its affiliates;

11) tax authorities;

12) banks;

13) counterparties under Yandex’ and its affiliates’ existing contracts and contracts under negotiation if strictly required for due diligence and/or “know your client” procedures;

14) various state and municipal authorities if strictly required to respond to their legitimate formal inquiries.

5. Transfers to third countries

Yandex transfers personal data of the members of the Board of Directors of Yandex to Russia and the United States which are considered as countries that do not provide for sufficient level of protection of data subjects’ rights under the European union law. When doing so, Yandex employs:

1) standard contractual section issued by the European Commission (decision 2004/915/EC) under Article 46 GDPR;

2) explicit consents of the members of the Board of Directors of Yandex under Article 49 GDPR.

Data subjects can get more information on the mechanisms of transfers to third countries by Yandex by sending a request with the use of contact details specified in section 1 of this Privacy Policy.

6. Storage periods

Yandex stores personal data of the members of its Board of Directors as long as it is required to achieve the purposes of the processing specified in section 2 of this Privacy Policy. It means that Yandex keeps their personal data for as long as they are members of the Board of Directors of Yandex and then, after they leave, their personal data are stored for a period of 10 years. However, Yandex needs to store some of personal data for the life of Yandex and this relates to the minutes and papers of meetings where data subjects’ names and contributions in meetings are recorded.

7. Basic rights of data subjects

The members of the Board of Directors of Yandex, in respect of their personal data, have rights to:

1) access;

(The data subject can ask Yandex to confirm whether or not Yandex processes their personal data. If so, the data subject can access these personal data and can ask Yandex to explain certain details of the processing.)

2) rectification;

(The data subject can ask Yandex to correct inaccurate personal data concerning him or her. If it complies with the purposes of the processing, the data subject can ask Yandex to complete incomplete personal data.)

3) erasure (‘right to be forgotten’);

(The data subject can ask Yandex to erase personal data concerning him or her under applicable law. For example, this applies if (1) the personal data are no longer necessary in relation to the purposes for which they were processed; (2) the data subject withdraws consent to the processing and there is no other legal ground for the processing; (3) the personal data have been unlawfully processed.)

4) restriction on processing;

(The data subject can ask Yandex to mark the stored personal data with the aim to limit their processing in the future under applicable law. This applies if (1) the data subject contests the accuracy of the personal data; (2) the data subject asks to restrict the use of the personal data when their processing is unlawful; (3) the data subject needs personal data to protect their rights when Yandex no longer needs the personal data; (4) the data subject has objected the processing based on the legitimate interests pursued by Yandex or by a third party.)

5) objection to processing;

(The data subject can object, on grounds relating to their particular situation, at any time to processing of personal data concerning him or her which is based on the legitimate interests pursued by Yandex or by a third party. Yandex shall no longer process the personal data unless Yandex demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.)

6) portability;

(When the processing is based on consent of the data subject or on a contract with the data subject, the data subject can receive the personal data concerning him or her, which he or she has provided to Yandex, in a structured, commonly used and machine-readable format and can freely transmit those data to another controller. Where technically feasible, the data subject can also ask Yandex to transmit the personal data directly to another controller.)

To exercise their rights, data subjects can contact Yandex with the use of contact details specified in section 1 of this Privacy Policy.

8. Withdrawal of consent

Where processing is based on consent (or explicit consent), the data subject has the right to withdraw consent at any time. The withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal. To withdraw consent, the data subject can contact Yandex with the use of contact details specified in section 1 of this Privacy Policy.

9. Right to lodge a complaint with a supervisory authority

When Article 77 of the GDPR applies, a data subject has the right to lodge a complaint with a supervisory authority in particular in the member state of the European Union of his or her habitual residence, place of work or of an alleged infringement of applicable law.

10. Necessity to provide personal data

Data subjects shall provide Yandex with personal data processed under this Privacy Policy so that Yandex can comply with applicable corporate and other laws as well as enter into and perform its relationship with them as members of the Board of Directors of Yandex. If data subjects do not provide Yandex with the relevant personal data, they cannot be members of the Board of Directors of Yandex.

11. Sources of personal data

Yandex collects personal data from data subjects themselves and obtains their personal data from the affiliates of Yandex assisting it in the achieving the purposes of the processing, mainly, from Yandex LLC registered at Leo Tolstoy street, Moscow, Russia, 119021.

12. Changes to this Privacy Policy

Yandex may change this Privacy Policy from time to time at its sole discretion. If so, Yandex notifies the data subjects about these changes by an appropriate method.